This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Whoami.EXE Execution From Privileged Process
Original Source:
[Sigma source]
Title:
Whoami.EXE Execution From Privileged Process
Status:
test
Description:
Detects the execution of "whoami.exe" by privileged accounts that are often abused by threat actors
References:
-https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
-https://web.archive.org/web/20221019044836/https://nsudo.m2team.org/en-us/
Author:
Florian Roth (Nextron Systems), Teymur Kheirkhabarov
Date:
2022-01-28
modified:
2023-12-04
Tags:
-'attack.privilege-escalation'
-'attack.discovery'
-'attack.t1033'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
OriginalFileName
:
'whoami.exe'
Image|endswith
:
'\whoami.exe'
selection_user:
User|contains
:
-'AUTHORI'
-'AUTORI'
-'TrustedInstaller'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high